712-50 · Question #151
A department within your company has proposed a third party vendor solution to address an urgent, critical business need. As the CISO you have been asked to accelerate screening of their security…
The correct answer is B. Vendor provided attestation of the detailed security controls from a reputable accounting firm. Option B is correct because a third-party attestation from a reputable accounting firm (e.g., a SOC 2 report from a CPA firm) provides independent, objective verification of the vendor's security controls - exactly what a CISO needs to make a fast but credible risk decision…
Question
A department within your company has proposed a third party vendor solution to address an urgent, critical business need. As the CISO you have been asked to accelerate screening of their security control claims. Which of the following vendor provided documents is BEST to make your decision:
Options
- AVendor's client list of reputable organizations currently using their solution
- BVendor provided attestation of the detailed security controls from a reputable accounting firm
- CVendor provided reference from an existing reputable client detailing their implementation
- DVendor provided internal risk assessment and security control documentation
How the community answered
(28 responses)- A11% (3)
- B79% (22)
- C4% (1)
- D7% (2)
Explanation
Option B is correct because a third-party attestation from a reputable accounting firm (e.g., a SOC 2 report from a CPA firm) provides independent, objective verification of the vendor's security controls - exactly what a CISO needs to make a fast but credible risk decision. Option A (client list) only confirms popularity, not security posture - plenty of breached vendors had impressive client rosters. Option C (client reference) is anecdotal and reflects one organization's experience with implementation, not a formal control assessment. Option D (internal documentation) is self-reported and unverified, giving you only the vendor's word about their own controls.
Memory tip: Think "trust but verify" - and who's doing the verifying matters. Only option B puts an independent, accountable third party on the line. When you see "attestation from a reputable firm," that's the auditor's reputation at stake, not just the vendor's.
Topics
Community Discussion
No community discussion yet for this question.